CUSTOMER STORY · TRUFFLEHOG ENTERPRISE
TextNow catches exposed credentials before landing in production
TextNow needed a consistent way to find exposed credentials across the systems its teams use every day. TruffleHog Enterprise replaced ad hoc scanning with broader coverage, credential verification, and a faster path from detection to remediation.
“The number of things that got dredged up that we hadn’t seen or touched in 4+ years I’ve been here was really surprising.”
Andrew Cotton, Head of Security, Compliance, and IT, TextNow
CUSTOMER SNAPSHOT
INDUSTRY
Telecommunications
DEVELOPERS
~100
TEAM
Security and IT
USE CASE
Secrets detection and remediation
HOW TEXTNOW USES TRUFFLEHOG ENTERPRISE
Finds secrets beyond source code
Scans source code, Jira, and Confluence, including attachments and personal spaces.
Prioritizes active credentials
Verification helps the team decide which exposures require immediate response.
Confirms remediation
Security can revalidate a credential after rotation before closing the incident.
01 · THE CHALLENGE
Periodic scanning left gaps in visibility
Before TruffleHog Enterprise, TextNow used periodic secrets scans as part of its security process. But without continuous coverage, the team did not always have a complete view of credentials exposed across historical code and collaboration systems.
The potential exposure surface also extended beyond source code. Credentials could appear in ticket attachments, build files, old documentation, and personal workspaces, making broader visibility difficult to achieve through periodic scanning alone.
02 · WHAT CHANGED
The proof of concept showed what the team was missing
After connecting Jira, TruffleHog Enterprise surfaced a credential inside a build file package in a ZIP attachment. In Confluence, it identified credentials in historical documentation and personal spaces that were not part of the team’s normal review process.
Credential verification made that broader coverage operationally useful. TextNow can use whether a credential is live to help decide when an exposure requires an immediate response and when it can be handled during normal working hours.
“If it’s not an active key, we don’t need to wake someone up in the middle of the night. If it’s an active key, yes, let’s wake somebody up so we can start some response to it.”
Andrew Cotton, Head of Security, Compliance, and IT, TextNow
03 · IN PRACTICE
An AI-built internal app exposed multiple credentials
24 hours
from commit to rotation — before the app reached production
A technical program manager used AI to build an internal application for tracking projects. The application needed access to several internal services, and its configuration included multiple credentials that were committed alongside the project.
When the application was committed to source control, TruffleHog Enterprise detected active credentials associated with several services. The security team worked with the application owner to rotate the affected credentials and resolved the issue within roughly 24 hours, before the application reached production or other engineers began using it.
“The day it got uploaded to our source code repository, we had the ticket and it was resolved within like 24 hours. Before it got to production, before any other engineers were touching it, and before anybody even started accessing the app.”
Andrew Cotton, Head of Security, Compliance, and IT, TextNow
04 · OUTCOME
A consistent safety net for credential exposure
TruffleHog Enterprise has also surfaced legacy API keys issued by vendors whose relationships with TextNow had ended years earlier but whose credentials were still active on the provider side. TextNow notified the affected vendors, and in at least two cases those vendors said they had been investigating anomalous activity involving keys that had not been properly terminated.
For TextNow, the broader change is that secrets detection no longer depends on periodic scanning alone. The team has wider visibility into where credentials can leak, a reliable signal for prioritizing active exposures, and a way to revalidate credentials during remediation.
“That’s one thing I don’t have to worry about right now.”
Andrew Cotton, Head of Security, Compliance, and IT, TextNow
KEY TAKEAWAYS
Three shifts for TextNow’s security team
Broader secrets visibility
Found credentials in places the team was not actively checking, including Jira attachments and historic Confluence content.
Urgent alerts only when warranted
Credential verification helps the team reserve immediate response for active exposures.
Faster remediation confidence
On-demand reverification lets security confirm that a credential was actually rotated before closing the incident.
Find exposed credentials before they become a bigger problem.
See how TruffleHog Enterprise helps security teams discover and verify exposed credentials across the systems their teams use every day.